Record summary

CVE-2020-22165 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHPHPGurukul Hospital Management System 4.0 - SQL InjectionCVSS 7.5

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain sensitive database information.

Impact

Successful exploitation allows attackers to access sensitive data from the database, potentially leading to data leakage and further compromise of the application.

Remediation

Upgrade to the latest version or apply proper input sanitization and parameterized queries to mitigate this vulnerability.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscve2020cvehmscmssqliphpgurukulvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
FOFA: title="Hospital Management System" && body="HMS"

Source: ProjectDiscovery

References

2